Newsletter | Develop Site

Ubercart sub-modules - Multiple Vulnerabilities

dev1961's picture

* Advisory ID: DRUPAL-SA-CONTRIB-2010-083
* Project: UC2Checkout, UCPaypal, UC Cart LInks (third-party modules in the
Ubercart Project)
* Version: 5.x, 6.x
* Date: 2010-Aug-11
* Security risk: Critical
* Exploitable from: Remote
* Vulnerability: Access Bypass, Cross Site Request Forgery

-------- DESCRIPTION
---------------------------------------------------------

English
SEO [en:field:taxonomy_vocabulary_4:book:label]: 
Tags [en:field:taxonomy_vocabulary_3:book:label]: 
Taxonomy upgrade extras [en:field:taxonomyextra:book:label]: 

Print - Local file read access

dev1961's picture

* Advisory ID: DRUPAL-SA-CONTRIB-2010-082
* Project: Printer, e-mail and PDF versions (third-party module)
* Version: 5.x, 6.x
* Date: 2010-August-11
* Security risk: Critical
* Exploitable from: Remote
* Vulnerability: Local file read access

-------- DESCRIPTION
---------------------------------------------------------

English
SEO [en:field:taxonomy_vocabulary_4:book:label]: 
Tags [en:field:taxonomy_vocabulary_3:book:label]: 
Taxonomy upgrade extras [en:field:taxonomyextra:book:label]: 

FileField Sources - Arbitrary Code Execution

dev1961's picture

* Advisory ID: DRUPAL-SA-CONTRIB-2010-081
* Project: FileField Sources (third-party module)
* Version: 6.x
* Date: 2010-May-19
* Security risk: Critical
* Exploitable from: Remote
* Vulnerability: Arbitrary Code Execution

-------- DESCRIPTION
---------------------------------------------------------

English
SEO [en:field:taxonomy_vocabulary_4:book:label]: 
Tags [en:field:taxonomy_vocabulary_3:book:label]: 
Taxonomy upgrade extras [en:field:taxonomyextra:book:label]: 

New ATutor 2.0 Modules

ernesto's picture

August 11, 2010

Three new modules for ATutor 2.0 were release today. They can be downloaded from the ATutor module site at the link below, or they can be imported directly from atutor.ca using the ATutor administrator's Module Manager. For more about modules, or to download them, visit:

http://www.atutor.ca/atutor/modules/index.php

*New ATutor Modules*

*Assignment Drop Box*

English
SEO [en:field:taxonomy_vocabulary_4:book:label]: 
Tags [en:field:taxonomy_vocabulary_3:book:label]: 
Taxonomy upgrade extras [en:field:taxonomyextra:book:label]: 

Kaltura - Information disclosure

dev1961's picture

* Advisory ID: DRUPAL-SA-CONTRIB-2010-078
* Project: Kaltura (third-party module)
* Versions: 5.x, 6.x
* Date: 2010-July-28
* Security risk: Less Critical
* Exploitable from: Remote
* Vulnerability: Information disclosure

-------- DESCRIPTION
---------------------------------------------------------

English
SEO [en:field:taxonomy_vocabulary_4:book:label]: 
Tags [en:field:taxonomy_vocabulary_3:book:label]: 
Taxonomy upgrade extras [en:field:taxonomyextra:book:label]: 

ATutor 2.0 Released

dev1961's picture

July 6, 2010

ATutor 2.0 has now been released. This version has some significant new features and represents a change of direction for ATutor software from its LMS roots to a collection of tools for developing online classrooms. ATutor administrators should upgrade their systems at their earliest convenience.

Follow these links for addition details, and read below for a list of new features.

*ATutor 2.0 Demo*
http://www.atutor.ca/atutor/demo.php

English
SEO [en:field:taxonomy_vocabulary_4:book:label]: 
Tags [en:field:taxonomy_vocabulary_3:book:label]: 
Taxonomy upgrade extras [en:field:taxonomyextra:book:label]: 

Pages